Using the Stream Control Transmission Protocol (SCTP)
As a cluster administrator, you can use the Stream Control Transmission Protocol (SCTP) on a bare-metal cluster.
Support for SCTP on OpenShift Container Platform
As a cluster administrator, you can enable SCTP on the hosts in the cluster. On Red Hat Enterprise Linux CoreOS (RHCOS), the SCTP module is disabled by default.
SCTP is a reliable message based protocol that runs on top of an IP network.
When enabled, you can use SCTP as a protocol with pods, services, and network policy. A Service object must be defined with the type parameter set to either the ClusterIP or NodePort value.
Example configurations using SCTP protocol
You can configure a pod or service to use SCTP by setting the protocol parameter to the SCTP value in the pod or service object.
In the following example, a pod is configured to use SCTP:
apiVersion: v1
kind: Pod
metadata:
namespace: project1
name: example-pod
spec:
containers:
- name: example-pod
...
ports:
- containerPort: 30100
name: sctpserver
protocol: SCTP
In the following example, a service is configured to use SCTP:
apiVersion: v1
kind: Service
metadata:
namespace: project1
name: sctpserver
spec:
...
ports:
- name: sctpserver
protocol: SCTP
port: 30100
targetPort: 30100
type: ClusterIP
In the following example, a NetworkPolicy object is configured to apply to SCTP network traffic on port 80 from any pods with a specific label:
kind: NetworkPolicy
apiVersion: networking.k8s.io/v1
metadata:
name: allow-sctp-on-http
spec:
podSelector:
matchLabels:
role: web
ingress:
- ports:
- protocol: SCTP
port: 80
Enabling Stream Control Transmission Protocol (SCTP)
As a cluster administrator, you can load and enable the blacklisted SCTP kernel module on worker nodes in your cluster.
Prerequisites
- Install the OpenShift CLI (
oc). - Access to the cluster as a user with the
cluster-adminrole.
Procedure
- Create a file named
load-sctp-module.yamlthat contains the following YAML definition:apiVersion: machineconfiguration.openshift.io/v1kind: MachineConfigmetadata:name: load-sctp-modulelabels:machineconfiguration.openshift.io/role: workerspec:config:ignition:version: 3.2.0storage:files:- path: /etc/modprobe.d/sctp-blacklist.confmode: 0644overwrite: truecontents:source: data:,- path: /etc/modules-load.d/sctp-load.confmode: 0644overwrite: truecontents:source: data:,sctp - To create the
MachineConfigobject, enter the following command:$ oc create -f load-sctp-module.yaml - Optional: To watch the status of the nodes while the MachineConfig Operator applies the configuration change, enter the following command. When the status of a node transitions to
Ready, the configuration update is applied.$ oc get nodes
Verifying Stream Control Transmission Protocol (SCTP) is enabled
You can verify that SCTP is working on a cluster by creating a pod with an application that listens for SCTP traffic, associating it with a service, and then connecting to the exposed service.
Prerequisites
- Access to the internet from the cluster to install the
ncpackage. - Install the OpenShift CLI (
oc). - Access to the cluster as a user with the
cluster-adminrole.
Procedure
- Create a pod starts an SCTP listener:
- Create a file named
sctp-server.yamlthat defines a pod with the following YAML:apiVersion: v1kind: Podmetadata:name: sctpserverlabels:app: sctpserverspec:containers:- name: sctpserverimage: registry.access.redhat.com/ubi9/ubicommand: ["/bin/sh", "-c"]args:["dnf install -y nc && sleep inf"]ports:- containerPort: 30102name: sctpserverprotocol: SCTP - Create the pod by entering the following command:
$ oc create -f sctp-server.yaml
- Create a file named
- Create a service for the SCTP listener pod.
- Create a file named
sctp-service.yamlthat defines a service with the following YAML:apiVersion: v1kind: Servicemetadata:name: sctpservicelabels:app: sctpserverspec:type: NodePortselector:app: sctpserverports:- name: sctpserverprotocol: SCTPport: 30102targetPort: 30102 - To create the service, enter the following command:
$ oc create -f sctp-service.yaml
- Create a file named
- Create a pod for the SCTP client.
- Create a file named
sctp-client.yamlwith the following YAML:apiVersion: v1kind: Podmetadata:name: sctpclientlabels:app: sctpclientspec:containers:- name: sctpclientimage: registry.access.redhat.com/ubi9/ubicommand: ["/bin/sh", "-c"]args:["dnf install -y nc && sleep inf"] - To create the
Podobject, enter the following command:$ oc apply -f sctp-client.yaml
- Create a file named
- Run an SCTP listener on the server.
- To connect to the server pod, enter the following command:
$ oc rsh sctpserver
- To start the SCTP listener, enter the following command:
$ nc -l 30102 --sctp
- To connect to the server pod, enter the following command:
- Connect to the SCTP listener on the server.
- Open a new terminal window or tab in your terminal program.
- Obtain the IP address of the
sctpserviceservice. Enter the following command:$ oc get services sctpservice -o go-template='{{.spec.clusterIP}}{{"\n"}}' - To connect to the client pod, enter the following command:
$ oc rsh sctpclient
- To start the SCTP client, enter the following command. Replace
<cluster_IP>with the cluster IP address of thesctpserviceservice.# nc <cluster_IP> 30102 --sctp